PeopleFinding your footing

The Quiet Workaround — When Users Route Around Policy

The unofficial spreadsheet usually finishes a job the sanctioned path left incomplete — that is human behaviour under friction, not a movie villain.

Ihor NesterenkoIT System Analyst6 min read · Aug 4, 2026

#Cybersecurity #InformationSecurity #Spreadsheets #ShadowIT #BusinessAnalysis

The unofficial sheet usually finishes what the official path left incomplete.
The unofficial sheet usually finishes what the official path left incomplete.

For years I treated an unofficial spreadsheet as a character flaw. Someone had ignored policy. Someone needed a talking-to. It took watching the same export appear before every supplier call — ERP open, PDF useless for filtering, ticket queue four days deep — to see the mature pattern: people were not rejecting security. They were finishing the last ten percent of a job the official path could not finish in time.

That is the quiet workaround. It looks like disobedience from a distance. Up close it is usually a map of friction. Once you see the map, the scare story loses its grip.

The Last Ten Percent

Most sanctioned systems are good at the middle of a process. They store the order, post the invoice, lock the approval. The awkward edge remains: a filtered extract for tomorrow's call, a chart the ERP cannot draw, a share to a supplier who has no account in the corporate tool.

When that edge matters and the ticket will not clear before the meeting, someone exports. The sheet becomes the working system for a few hours — and sometimes for a few months.

You have probably done a version of this yourself. Not because you dislike controls. Because the meeting was real and the sanctioned path was not ready.

The naive reading is carelessness. The mature reading is incomplete design. The export is evidence that a real job outran the approved path.

A quiet workaround is evidence the official system is incomplete for a real job — not that the user is careless.

Spreadsheet Systems as Human Behaviour

Call the pattern what it is: a spreadsheet system that people invent because the official one stops short. It is not glamorous. It is not a nation-state plot. It is ordinary delivery under time pressure.

The UK's National Cyber Security Centre is plain about this. Shadow IT is rarely malicious intent; it is normally staff struggling with sanctioned tools or processes, adopting unofficial measures to complete the work. Common drivers include slow request processes, missing third-party share paths, and approved tools that lack required functionality.

That framing matters because it changes the first question. Not "who broke policy?" First: "what job could not finish on the sanctioned path?"

You will hear the opposite framing in corridor talk: "if they cared about security they would wait." Waiting is not always available. A supplier call at nine does not move because the report ticket is still in triage. The person who exports is choosing between an incomplete meeting and an incomplete policy story. Most choose the meeting.

Malice still exists. Deliberate theft and concealment need a separate managerial path. Collapsing every unofficial sheet into that story teaches people to hide the next export — and your visibility drops. Handover week multiplies the same ordinary habits under a leaving date; the weekday version without a departure still maps friction, not a spy story.

NIST's usable-cybersecurity work makes the same point from the other direction: when security burden rises without usable alternatives, people invent less secure workarounds to keep working. The famous watch-under-the-mouse screen-lock story is not a joke about stupid users. It is a story about a policy that ignored how people actually sat at a desk.

The Spreadsheet That Finished the Last Ten Percent

Picture a logistics analyst preparing a supplier call. The ERP holds the order lines. It will print a PDF. It will not let her filter open lines by warehouse and paste a clean list into the agenda by 9am. The access ticket for a custom report sits in a queue that averages four days.

She exports to a sheet the night before. She shares it with "anyone with the link" because the supplier contact is outside the SSO boundary and the sanctioned guest process is another ticket. The call goes well. The sheet remains in a shared drive, then in an email thread, then in a second copy "just for finance."

Nothing in that sequence requires a villain. It requires a missing filtered extract and a missing safe share path. The unofficial sheet finished the job. It also created unmanaged copies — a real risk, and a different kind of problem from "Bob is careless."

Notice the sequence after the call. Nobody planned a shadow system. They planned to delete the file on Friday. Friday arrives with another exception. The temporary sheet becomes the place where corrections live, because writing them back into the ERP is another queue. That is how a one-night export becomes the working ledger.

NIST's CSF 2.0 implementation examples treat unofficial uses of technology as something to identify in the asset lifecycle — unofficial tools that meet mission objectives. Identification is the start of governance. Moral panic is not.

Friction Map, Not Blame Map

When you find the quiet workaround, run three questions before you escalate tone.

What job was unfinished? Name the concrete outcome — filtered list, chart, third-party share — not the tool brand.

What blocked the sanctioned path? Time, permission, missing feature, or a process that cannot meet the deadline. NCSC lists these same families of friction.

What would make the official path usable in time? A saved report, a guest share that clears in hours, an export with row-level controls. If you cannot name a usable fix, a crackdown will not produce compliance. It will produce quieter channels — USB, personal cloud, a phone photo of the screen.

Write the answers down once. If the same job appears twice in a fortnight, you are not looking at a one-off shortcut. You are looking at a standing gap between policy and delivery.

A delivery lead can ask these in a standup. You do not need a CISO title to map friction. You need curiosity without prosecution. The point is not to become a junior auditor. The point is to stop the conversation from ending at "policy was broken" when the useful sentence is still missing.

What Makes Honesty Possible

NCSC's advice is unfashionable and correct: do not reprimand people for being forced into shadow IT; blame reduces what peers will tell you next. The learning opportunity is the underlying need — then bring a supported service above board that meets it.

Stricter locks without a usable path do not restore control. They move the same job into a place your tools cannot see.

Punishing discovery of the workaround reduces visibility faster than it reduces risk.

This is footing-level security awareness, not an architecture programme. You are not being asked to redesign zero trust this afternoon. You are being asked to stop reading every unofficial sheet as a character indictment, and to start reading it as a unfinished-job report.

Containment still matters when sensitive data sits on an open link. Lock the share, rotate what must be rotated, and keep the conversation about the unfinished job. Specificity protects people and protects the estate. Scare stories about shadow IT as theatre do neither.

The quiet workaround is a signal that the official path stopped short of the work.

More in People

← Back to hub